Fake Minecraft Clients Push WeedHack Malware

Infosecurity Magazine · Medium sophistication
Last updated August 25, 2026

Attackers are tricking Minecraft players into downloading malware by impersonating popular Minecraft clients and resellers in Google search results. Even after the campaign’s command-and-control infrastructure was taken down, the operation continued by shifting distribution to common file-hosting platforms like Discord, MediaFire, GitHub, and Dropbox.

Key findings

  • McAfee observed ongoing activity from the WeedHack campaign after an earlier takedown of its command-and-control infrastructure.
  • Attackers used SEO poisoning and fake websites impersonating legitimate Minecraft clients to put malicious downloads in front of gamers.
  • The campaign shifted to distributing malware via mainstream file-hosting services, especially Discord, plus MediaFire, GitHub, and Dropbox.
  • Some fake sites lured users with offers like free versions of paid tools or cracked software.

Who’s being targeted

  • Commonly targeted roles: Gamers/Players, Students, Helpdesk/IT support (endpoint protection guidance), Parents/Guardians (home device safety).
  • Affected industries: Gaming, Consumer/End users, Education (students/gamers).
  • Attack channels: website, discord.
  • Impersonated: Legitimate Minecraft client/reseller site (e.g., a popular client such as “Xenon Client”), A Minecraft mod/client uploader using Discord file hosting.

Awareness takeaways

  • Only download mods/clients/tools from trusted, official sources (not “top Google results” or lookalike sites).
  • Be skeptical of “free” offers for paid tools/cracked software, these are common bait for malware.
  • Keep security software enabled and scan downloads before opening them.
  • Check links carefully for lookalike domains before downloading anything.

Red flags to watch for

  • Arrives via a lookalike website that imitates a known Minecraft client/reseller
  • Promotes “free versions of paid tools” or “cracked software” as a lure
  • Download is pushed via search results influenced by SEO manipulation
  • Uses a general-purpose file-hosting link instead of an official project site
  • Unexpected executable download for a “client/mod”
  • Link origin does not match the official source for the tool
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google a Minecraft client like “Xenon Client” and click the top result, without thinking. That’s the WeedHack trap. WeedHack uses SEO poisoning and lookalike Minecraft client sites that promise free or cracked tools. You click download…and the file actually comes from Discord, MediaFire, GitHub, or Dropbox, not the real project site. Here’s the tell: a “free” version of a paid Minecraft tool, hosted on a generic link like Discord or MediaFire, and the URL doesn’t match the official client site. If the download is an unexpected EXE for a mod, that’s your red flag. One move: only download Minecraft clients and mods from the official project site you type in yourself, then let your security software scan the file before you run it.

Similar attacks

Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Fake Minecraft Sites Keep Spreading WeedHack

Fake Minecraft Sites Keep Spreading WeedHack

Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links…

September 8, 2026
Fake Downloads and Extensions Steal Sessions Fast

Fake Downloads and Extensions Steal Sessions Fast

The article highlights real, ongoing campaigns where attackers trick people into installing malware via fake software-download websites and a disguised browser extension. These lures are used to steal credentials, browser cookies, and authenticated sessions, letting attackers take over accounts…

September 11, 2026
Placeholder Domain Now Pushes ClickFix Malware

Placeholder Domain Now Pushes ClickFix Malware

A commonly used documentation placeholder domain, third-party.com, was registered by an unknown party and is now serving a ClickFix social-engineering lure to Windows users. The page pretends to run a Cloudflare security check, silently poisons the clipboard, and tells victims to paste and run a…

September 24, 2026
Fake LastPass GitHub Drops Rapuncel Stealer

Fake LastPass GitHub Drops Rapuncel Stealer

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets,…

September 23, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026